| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full administrator-equivalent access to the plugin's MCP tool surface and all exposed WordPress content, users, and options. This is exploitable by combining the publicly accessible Dynamic Client Registration endpoint, which allows unauthenticated callers to register arbitrary OAuth clients with an attacker-controlled redirect_uri, with the unprotected authorization endpoint to complete the full OAuth flow without any administrator interaction. |
| Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. |
| Contributor SQL Injection in eRoom <= 1.7.1 versions. |
| Subscriber Broken Access Control in eRoom <= 1.7.1 versions. |
| Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. |
| Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. |
| Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. |
| Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. |
| Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. |
| Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. |
| Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. |
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. |
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS.
This issue affects Hubbub Lite: from n/a through 1.36.3. |
| Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard administrative controls. |
| InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem directories and use HTTP response codes to determine file existence and readability, bypassing multi-user mode access controls. |
| A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process. |
| Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions. |